In plain words: Proofs collected here show that any model trained on messy, user-made data full of private details and fake accounts must memorize much of it to stay accurate. So today's big AI models cannot be both highly accurate and strongly secure.
Abstract
Large AI Models (LAIMs), of which large language models are the most prominent recent example, showcase some impressive performance. However they have been empirically found to pose serious security issues. This paper systematizes our knowledge about the fundamental impossibility of building arbitrarily accurate and secure machine learning models. More precisely, we identify key challenging features of many of today's machine learning settings. Namely, high accuracy seems to require memorizing large training datasets, which are often user-generated and highly heterogeneous, with both sensitive information and fake users. We then survey statistical lower bounds that, we argue, constitute a compelling case against the possibility of designing high-accuracy LAIMs with strong security guarantees.
El-Mahdi El-Mhamdi, Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Lê-Nguyên Hoang, Rafael Pinot, Sébastien Rouault, John Stephan
arXiv:2209.15259 · cs.LG, cs.AI, cs.CR · submitted Sep 30, 2022 · updated May 9, 2023
abstract · pdf · html · 40 pages